CVE-2026-25592: Critical Semantic Kernel Flaw (CVSS 10.0) Allows File Overwrite
ID: b36c552b-b67d-5cc3-b27c-1c5a9c2a6d84
STIX ID: report--b36c552b-b67d-5cc3-b27c-1c5a9c2a6d84
Feed Name: securityonline.info
Threat Score
Microsoft warned of CVE-2026-25592, a critical (CVSS 10.0) arbitrary file write vulnerability in Semantic Kernel.NET's SessionsPythonPlugin that fails to validate paths for DownloadFileAsync and UploadFileAsync, potentially allowing agents or attackers to overwrite sensitive host files; the issue is fixed in Microsoft.SemanticKernel.Core v1.70.0 and a temporary workaround is to implement a Function Invocation Filter to whitelist allowed localFilePath values.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
